Gmail intercepted me and claimed to be worried that they couldn't recognize the device I was using. According to the flow, they wanted me to verify my identity in one of three ways: (1) I could verify the backup email address associated with the account; (2) if unable to do that, I could provide the 2FA code sent to that same backup email address (how would I be able to know this without being able to know what the address was?); or (3) I could provide a phone number -- previously unknown to Google -- on the spot, and then provide the 2FA code sent to that brand-new phone number. (How is this supposed to help them verify my identity?)
I went for option (2), the email 2FA code. After providing the code, I was informed that, before signing in to my existing gmail account, I must also provide a phone number and enter the 2FA code sent to my new phone number.
So I went back and went for option (1), typing in my backup email address. Same thing happened. Because Google "couldn't recognize the device I was using", I was not allowed to sign in to an account I obviously controlled without providing a phone number with absolutely zero authentication value.
I did find a workaround. If you attempt to sign in to an account afflicted in this way in an incognito browser window, Google will, for the moment, allow it.
"Don't be evil" is long gone.
Or of course, just send the code to anyone and SS7 hijack that specific text message. You aren't hacking them, after all, you're hacking yourself or someone else.
What does this mean?
I currently have an old (infrequently used) gmail account, with a valid recovery email, that I cannot log in to at all.
I don't have (or want) 2FA set up for it.
I tried an incognito window just now, and same problem ):
I am one of those people using option 2, by virtue of keeping a lot of old email accounts that I have set up to forward to my main account. So I don't usually need to remember which account if was, and just wait for the email to come through from the void
I suspect it's some work-life balance enhancing thing. :D
I don't really mind, since it also helps me bash Google services in front of my clients who still use them, without being aware of these failure modes.
Personally speaking, it's absolutely a no go service. I can probably handle service loss at home quite fine, but if I relied on google or other services with these "anti-abuse" features while traveling that would be very stressful. I usually print out everything important before departing so I don't rely on any electronics, anyway, because none of it is as reliable and as quickly accessible as a piece of paper or a bunch of cash.
Their expressed policy makes an interesting contrast with their behavioral policy of freaking out and locking you out of your own account if you ever try to sign in on a device they suspect might not belong to you.
And of course, they're godawful at recognizing whether a device belongs to you. They freak out and send me "urgent" emails (on a different gmail account) whenever my phone switches between wifi and the cell network. Responding "yes, that was me" does nothing to prevent this.
The fact that Google is inconsistent about it is probably due to Google generally not being good in UX and frequently making these kind of mistakes where it seems there are multiple teams doing their own things incompatible with each other.
You misspelled "product lifecycle management." Google's lack of accomplishments in this department is a testament to their research, innovation, and committment to the disciplines of Six Omega (6ω) process strategies.
Never doing any buissness with ms again.
No github for you then ;)
And if you're talking about the hosted solution... we use that at work. We have what are effectively outages once a week on average.
I like the way Gitlab as a company is run and I really want to like it but... I use gitea at home and we're actively migrating away from it at work.
Don't use a major cloud provider. That's $20/mo with Digital Ocean.
Can confirm that gitea's pretty nice. It's not heavier than a web-based git host should be. I really like that it has a SQLite database option, since that's plenty good enough for low-tens of users and operationally simpler.
Are you insinuating that Google has this convoluted verification flow to intentionally harm people in some way? Or even to intentionally harm privacy or further business goals at users' expense?
Or are you just using "evil" to refer to anything you don't like?
That may not be what they intend, but that is result, regardless.
Yes (and obviously).
Google, and other SaaS, have used such dark patterns to collect more user identity data (user profile info is what they ultimately sell - even if sold to advertisers "anonymized", the profile is richer and more worth the more data they have on you).
Google forcing you to enter a phone number is dishonest/hostile and has absolutely not the slightest to do with any desire to make your account more secure.
It's basically just Google holding your account hostage to get your phone number.
https://www.eff.org/deeplinks/2019/07/fixed-ftc-orders-faceb...
So, since it isn't effective for its stated purpose, are there other reasons it could be in place?
Now I can't use option 1 or 2 because I don't have internet access until Google approves my sign in. I can't use option 3 because I don't have a SIM card that would work locally. Thankfully Facebook login worked.
We had incidents in the past just because the colleague had given the number to Google and those were corporate accounts.
Every time a service moves to SMS or phone calls for 2FA a cry can be felt across the universe by any security engineer/cryptographer.
If you are a person responsible for this: please don't. If my antiquated bank that is insured and doesn't really care can understand this, so can you, if you care just a bit.
The process has a security hole by design: SIM cards can get damaged/lost (usually with the phone) and you wouldn't want to lose your number just because you lost your phone or damaged your SIM card by accident. This hole is typically exploited by attackers after they have identified a high-value target. You basically outsource the control over your account to a telco employee.
Still can’t prove what happened but someone ported my number from my carrier to Sprint and it took easily 18 hours to undo it. And it required convincing sprint, which I had no affiliation with, that the original transfer was not intended, and that yes I want to reverse it out.
Crazy painful.
Suggestion to phone companies: When receiving such requests email and text the user saying "we've had a request to transfer your number, contact us if not you" rather than just cracking ahead.
You literally do not have a choice, last time I checked you had to setup SMS 2FA first. Once you’ve done that you can setup a better method and remove the SMS, but you have to remember to do it.
> If my antiquated bank that is insured and doesn't really care can understand this, so can you, if you care just a bit.
My bank certainly has not gotten that memo.
Two options from the top of my head:
1. you have email forwarding configured so received mails will be delivered to another account. That's generally configured in the settings of the provider (I.e. directly under account settings in Gmail iirc)
2. You have a logged in device which receives mails through an application password. You cannot read it out because it's masked and even if you could, it wouldn't help you because it's only allowed to receive mails, not login.
I don't think this is particularly rare, honestly.
But yes, it is obnoxious.
I can't think of another way not to get locked out in case I ever lose my phone.
Google, Paypal and a few others seem to be the worst offenders at "protecting me".
Requiring cell phone numbers isn't about anti-spam or 2FA or anything else these services and sites claim.
It's about linking your account to a real person identity, so they can sell that to someone - either live, or later when they get bought out (privacy policies almost always have a clause that allows them to just fork over all your info to whoever buys the company.) "Where was phone number 111-555-1212 at any point in time" is really valuable these days.
SMS for 2FA is less secure because cellular accounts are almost trivial to take over. Carriers never intended for their accounts to become so important to security. These days you can get a second password added to prevent shipping out a new SIM or transferring the account, but that's bypassable by a cellular store on the corner, and poorly implemented (my carrier just adds it as a CUSTOMER VISIBLE AND EDITABLE comment on my profile. WTF?)
If you get someone's unlocked cell phone or a SIM card, you can get access to their email account, their bank and credit cards...damn near everything. How fast can you lock and wipe your phone if it was ripped out of your hands while you were using it in a public place?
Yeah, this can't be emphasized enough. Phone numbers are established as universal identifiers. Discord is sitting on a giant heap of personal information including DMs from millions of young people. It is all centralized, both in terms of data, and in terms of accounts (instead of them having to correlate an account between multiple forums, most of which volunteer run and they don't turn over non-public data for money), and also associated with phone numbers. Making multiple accounts for different areas of life is made hard. Beautiful for whoever has access to the data.
The security side is a total lie as well. Your post made me think about the biggest risk for myself and, like many people I know, I put my email address on my lock screen so that if I lose my phone someone can get it back to me. Now it just clicked for me and I realize I need to change that because if I lose my phone someone has everything they need to recover a lot of my online accounts. My Google, Microsoft, Amazon, etc. accounts all use that same email address and all they need to do to perform SMS recovery is put my (unlocked) SIM in another phone.
I first noticed phone number abuse with facebook, which asks for a phone number for "security" but then uses it to match you with advertisers.
It's the same scam that sites have been running for years where you have to use an email address as a user login, and that address is instantly added to spam lists.
"Sign in with Apple" is hilariously useless since privacy-violating apps can just require a phone number for "security" or "verification" purposes.
Apple is one of the only companies with both the ability and a possible incentive to push back on that behavior. I wonder if they will.
Oh it’s even worse than that. I have a land line that I use exclusively for when I’m forced to give a phone number (and also for faxing doctors and lawyers which is apparently still a thing). Many internet forms reject it because it can’t accept text messages. Yeah, that’s the fucking point. I don’t want text messages from your shitty service. It’s still a legitimate phone number you can call. Don’t ask for a phone number if you won’t actually accept a valid phone number! FFS!
And often I'll run into problems with silently failed messages because they don't accept the number.
I’ve never ‘needed’ a credit score unless I was requesting a line of credit. I’m which case a credit score is better than the alternative where I need to personally know someone that the lender already trusts and trusts their ability to trust other people.
You don’t ‘need’ a credit score but if you want a line of credit then it’s good to have. Otherwise you get the products that they offer to high risk individuals which costs a pretty penny.
I've also heard tell of employers using credit checks to evaluate potential employees though I haven't researched that.
Sure, it’s short term credit (sub 30 days), but it’s still credit.
However since all of the OP's examples involved credit (car rental post-pay, phone usage post-pay, etc.) then in those cases trust===credit score. Without a credit score, you're basically asking someone to trust blindly that you'll pay back a debt since there's no track record of your ever paying back debts.
Just in case you are not aware, you can receive verification SMS on your laptop as well! On Windows 10 there is a built-in app simply called "Messaging" which shows you all the SMS received on that number. I'm sure something different exists for other OSes.
This is what I do when asked for a verification number and there is absolutely no way around it, I just put the phone number of my laptop's SIM card, that way I don't have to worry too much about spam too because I will never use that number in a real phone.
They seem less common nowadays, since a tablet or tethered phone covers most use cases.
But thank you none the less.
It's makes a lot of sense for a high-value target like banking to require 2FA, but SMS is the worst way to do it.
I've had a Google Voice number for so long it's the only voice number I have these days. I can't say it's a recent experience that it doesn't work with certain things though it has been a recent experience the things are aware it doesn't work and will alert you. Overall though I've yet to run into anything I couldn't use an alternative method for authentication be it luck (e.g. got into Discord before they required phone numbers) or email or calls being a thing (and working when text doesn't).
Ironically the biggest PITA I had was when I decided to migrate my primary cell number to Google Voice it was my fallback contact number. Thankfully I only ran into that as an issue once and was able to get back in to set up Google Authenticator (which was also new and hip at the time).
Anyway, that's a lot of words to say "MVNO" is for sure not identical to "any other cellular network" for a certain class of interested parties, in the same way that pre-paid credit cards are not the same as other credit cards
You can refuse to provide it (unless it's required for tax/employment purposes) but whoever's asking can then just refuse to transact with you.
Since you can change phone number without changing SIM (I don't know if it's global, but in the UK you just text a certain number for a transfer 'PAC' code) and clone them.
https://github.com/freedesktop/ModemManager/blob/master/NEWS
Completely agree about the walls of commercial surveillance closing in though.
Same with getting NMEA sentences off the GPS, I have to use windows' idiotic location API for that. 9600 baud serial worked just fucking fine, I don't understand why that isn't available as well. It's so annoying that I have to fight this hard for functionality my hardware already has.
Refs:
https://whirlpool.net.au/wiki/sierra_advanced_gps
https://forum.openwrt.org/t/problem-accessing-gps-data-from-...
https://gitlab.freedesktop.org/mobile-broadband/ModemManager...
[0] https://www.phoronix.com/scan.php?page=news_item&px=Intel-M....
[0] says it also supports MBIM which is supported ootb with ModemManager and somewhat recent kernels. If your BIOS does not allow this, you probably need to tape over the PCIe-Pins with some non-conductive tape.
[0] https://fccid.io/ZMOL860GL/User-Manual/Users-Manual-3993200....
Well of course -- the SIM is the (as others have pointed out, "currently assigned", yada yada) phone number. So what else would any device with a working SIM slot be treated as, than a cellular device?